Wind River Support Network

HomeDefectsLIN1018-8277
Fixed

LIN1018-8277 : Security Advisory - cluster-glue - CVE-2010-2496

Created: Oct 18, 2021    Updated: May 13, 2022
Resolved Date: Oct 25, 2021
Found In Version: 10.18.44.1
Fix Version: 10.18.44.23
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.

CREATE(Triage):(User=admin) CVE-2010-2496 (https://nvd.nist.gov/vuln/detail/CVE-2010-2496)

CVEs


Live chat
Online